cbcvebase.
CVE-2019-9506
published 2019-08-14

CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from…

high8.1CVSS 3.1
AVAACLPRNUINSUCHIHAN
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

Affected

150 ranges· showing 25
VendorProductVersion rangeFixed in
appleios
appleiphone_os
applemac_os_x
applemac_os_x
applemac_os_x
applemacos_mojave_10.14.6_security_update_2019-004_high_sierra_security_update_2019-0
appletvos
appletvos
applewatchos
applewatchos
bluetoothbr_edr5.1 – 5.1
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.2.6-1 (bookworm)linux 5.2.6-1 (bookworm)
googleandroid
huaweialp-al00b_firmware< 9.1.0.333\(c00e333r2p1t8\)9.1.0.333\(c00e333r2p1t8\)
huaweiares-al00b_firmware< 9.1.0.160\(c00e160r2p5t8\)9.1.0.160\(c00e160r2p5t8\)
huaweiares-al10d_firmware< 9.1.0.160\(c00e160r2p5t8\)9.1.0.160\(c00e160r2p5t8\)
huaweiares-tl00c_firmware< 9.1.0.165\(c01e165r2p5t8\)9.1.0.165\(c01e165r2p5t8\)
huaweiasoka-al00ax_firmware< 9.1.1.181\(c00e48r6p1\)9.1.1.181\(c00e48r6p1\)
huaweiatomu-l33_firmware< 8.0.0.147\(c605custc605d1\)8.0.0.147\(c605custc605d1\)
huaweiatomu-l41_firmware< 8.0.0.153\(c461custc461d1\)8.0.0.153\(c461custc461d1\)
huaweiatomu-l42_firmware< 8.0.0.155\(c636custc636d1\)8.0.0.155\(c636custc636d1\)

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv8.1HIGH